Large alphabet quantum key distribution with 
two-mode coherently correlated beams 

Vladyslav C. Usenkof^and Bohdan I. Levf 

o . 

O ■ f Institute of Physics, National Academy of Sciences of Ukraine, 

46 Nauky pr, Kyiv 03028, Ukraine 

^ . February 1, 2008 

(N 

> 

[ — ' Abstract 

o : 

. The large-alphabet quantum cryptography protocol based on the 

\ two-mode coherently correlated multi-photon beams is proposed. The 

alphabet extension for the protocol is shown to result in the increase 
of the QKD effectiveness and security. 
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1 Introduction 

- T-^ - 

X 

^ , Quantum cryptography [3], being the first practical realization of quantum 

physics at the single quanta level, is the art of creating data channels phys- 
ically secure against eavesdropping. Most of its successful practical realiza- 
tions are based on the use of single photon information coding though optical 
fiber links thus being based on a weak laser pulses. The security of the pro- 
tocols is based on the state perturbation during the eavesdropping or the 
measurement correlations analysis with the Bell inequalities check [2>. Since 
key bits are encoded in the single photon states the appearance of the addi- 
tional photons may seriously undermine the protocol security by leading to 
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the successful listening-in because additional photons' states can be imper- 
ceptibly measured by an eavesdropper. Thus the security reasons require the 
minimizing of the multi-photon pulses appearance probability making most 
of the pulses empty, which limits the key rate and results in an additional 
error rate caused by the single-photon counting detectors, which are inclined 
to "dark counts", clicking when the photon is missing [3]. 

This leads to some contradiction between the effectiveness and security 
of the existing quantum key distribution (QKD) schemes. The contradiction 
can be overcame by using multi-photon pulses and establishing the chan- 
nel security on the realistic basis of multi-photon statistics rather then the 
fermion pairs statistics which the first QKD protocols where starting with. 

Besides avoiding empty pulses by making carrier beams more intensive 
another point for increasing the effectiveness of quantum communications 
and QKD in particular is the alphabet size, which can be extended beyond 
the usual two-letter one, which corresponds to a classical bit. It was shown 
that the large-alphabet coding essentially increases the bit rate of a quantum 
channel with no loss in security even in the case of a single-photon polariza- 
tion coding 

In this work we prove the effectiveness of the alphabet extension for 
the new multiphoton QKD protocol which was proposed recently j3 Ej on 
the basis of the special beam states called two mode coherently correlated 
(TMCC). These states have the strong correlation between the photon num- 
bers in each of the two spatially parted modes. This correlation leads to 
the fact that laser shot noise shows itself equally in the both of the modes 
thus enabling the use of a TMCC-source as a generator of some random 
bit sequence which is then shared between two legitimate parties who per- 
form independent photon-number measurements on each of the modes and 
extract the key bits from the measurement results comparing them to the 
constant average photon number. The quantum channel capacity for the 4- 
and 8-letter extended alphabets is estimated. The eavesdropping attacks on 
the extended-alphabet TMCC-channels are considered in terms of the intro- 
duced QBER. It is shown that the alphabet extension leads to the increase 
of the effectiveness of the QKD protocol providing channel capacity of up to 
3 bits per pulse. Moreover the alphabet extension strengthen the protocol 
security against the intercept-resend attacks by making eavesdropper intro- 
duce larger QBER on each successfully intercepted bit exceeding 70% QBER 
per bit for the 8-letter alphabet. 
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2 Protocol 



The TMCC-protocol is based on the use of a special states of hght, the two 
mode coherently correlated ones. Such states were mathematically studied 
by Agarwal [HI IHl- They are defined as fully correlated and at once the 
eigenstates for the product of annihilation operators of the both modes. The 
latter condition makes them the special case of the wider class of the two- 
mode correlated states, also referred to as twin beams, which are broadly 
investigated in the past time [101 HH [12] and are usually obtained in the 
process of parametric down- conversion (PDC) in nonlinear crystals. 
The TMCC-states can be presented through series by Fock states: 

|A)= , E-rl^^) (1) 



V'^(2|A|)n=o ^! 



Here we use the designation \nn) = \n) ^ ® \n) 2, where \n)^ and |n)2stand 
for the states of the l*** and 2"'^ mode accordingly, represented by their photon 
numbers. 

The main feature of the states is that only the terms with equal photon 
numbers in the both of the modes are present in the expansion. This leads 
to the strong correlation between the observables concerned with each of the 
modes. At the same time the TMCC states differ from the usual two-mode 
correlated coherent states, because the average for any of the linear in field 
observable (e.g. the vector-potential) is equal to zero for each of the TMCC 
modes [1] . Thus each of the modes is not coherent to itself, but as the square 
in field observables (e.g. correlation function, momentum, energy) have non- 
zero average values, the TMCC states possess the second order coherence 
and so can be referred to as the coherently correlated states. 

The separate intensity measurements on each of the beams give the results 
which are proportional to the average of the = a^a, which corresponds to 
the number of photons in the mode. The probability distribution for different 
photon numbers detection is 



PniX) = T7^:-zk- (2) 



|2n 

/o(2|A|) nP 

The photon statistics for each of the beams is sub-Poisson as confirmed 
by the Mandel parameter, which is negative even for the small intensities 
jH [H]. This fact can be useful for the TMCC state identification and the 
quantum channel eavesdropping detection. 

The shot noise photon number fluctuations in the TMCC modes enable 
the use of the TMCC source as a generator of a random key encoded in the 



3 



photon numbers value. The strong correlation between the independent mea- 
surements of two modes makes it possible to securely distribute such random 
key between two remote legitimate users, Alice and Bob. The security of 
the quantum channel is based on the fact that intermediate photon measure- 
ments will perturb the states which can be checked locally by measurement 
statistics |5j. 

The simple protocol based on the two mode coherently-correlated states 
was described jij as follows: Alice and Bob simultaneously start the indepen- 
dent photon number measurements each on the corresponding TMCC mode. 
They compare the obtained photon number values for each next unit time to 
the average which is constant during the overall key transmission procedure. 
If the obtained number is larger than the average, the next bit is considered 
to be equal to "1". If the photon number for the next time window is less 
than average, the corresponding bit is equal to "0". Thus, the protocol uses 
the two-bit photon number alphabet coding by the multiphoton two mode 
coherently correlated states. 

The state coherence is an important feature of the TMCC-protocol distin- 
guishing it from the existing single-photon incoherent state protocols because 
coherence allows establishing the security for the multiphoton pulses trans- 
mission since the state perturbation leads to the decoherence. The loss of 
coherence can be revealed by checking the state statistics which can be done 
even locally by estimating differences between the obtained and expected 
state density matrices 0. 

3 Alphabet extension 

The classical information channel is well known to be described by the Shan- 
non mutual information between the observables of some classical macro- 
scopic systems. The measurements on such systems return the probability 
distributions for the sets of the observables' discrete values. These value 
sets when used for encoding and decoding the information are called the al- 
phabets which contain the discrete values of the observables as the letters. 
The input-output mutual information depends on the observables' Shannon 
entropies: 

I{X;Y) = H{X)-H{X\Y), (3) 

where H{X) is the input observable entropy and the H{X\Y) is the mu- 
tual entropy of the input relative to the output which describes the informa- 
tion loss in the channel: 
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H{X\Y) 



Y.p{x,y)logp{x\y) = H{X,Y) - H{Y). 



(4) 



Since H{X\Y) depends on the probability distribution of the values set 



it depends on the alphabet size and increases with the increase of the 
number of its letters. 

This discourse clearly fits the quantum channels which differ from the 
classical ones by the fact that quantum observables, being the parameters 
of the quantum microscopic states, are used for information encoding and 
decoding. Since quantum cryptography deals with the key sharing across 
the quantum channel it can also gain from the alphabet expansion. 

In 1999 Bechmann-Pasquinucci and Tittel |6 proposed the use of a larger 
alphabet for the BB84 single-qubit protocol [1 , which is extended on the four- 
level quantum systems - the so-called quantum quarts (qu-quarts). Alice still 
selects randomly between the two possible bases, but she is now preparing one 
of the four states thus making eight possible choices for the qu-quart based 
protocol instead of the four choices for the qubit-based one. It was shown that 
such a development of the BB84 protocol increases the information flux and 
makes the QKD scheme more secure against realistic eavesdropping because 
eavesdropper introduces the much higher QBER for the given amount of the 
acquired information. 

Lately in 2003 Sych, Grishanin and Zadkov [7] made the further develop- 
ment of the single-qubit QKD scheme by proposing the use of the continuous 
alphabet for the key bits coding. The idea was to identify key bits from 
the unselected qubit states which was shown to result in the increase of the 
protocol effectiveness, security and reliability at noisy channels. 

Thus it makes it clear that the protocol extension may be quite useful 
for the TMCC-based protocol especially since the multi-photon states in the 
Fock presentation can be considered as the multi-dimensional systems. 

The maximum Shannon entropy of a photon-counting beam measure- 
ment, i.e. the highest possible information capacity for a channel built on 
such beams can obviously be achieved if each of the different photon-number 
events are identified as the different measurement outcomes and correspond 
to the different alphabet letters. In other words, the m-letter alphabet for 
the m-photon state will give the maximum information which can be encoded 
into and transmitted by such a state. For the TMCC-beam this maximal in- 
formation will be 



H{X) 



P{x) logp(x) 



(5) 
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2n 
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lA 



2n 



(6) 



„^o/o(2|A|) "^/o(2|A|) ' 

The dependence of this highest possible information gain of a state mea 
surement on the average photon number of the state is given at (HJ. 
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Figure 1: Maximum Shannon entropy of the photon- number measurements 
on the TMCC-states 



One can easily see that depending on the beam intensity, the TMCC state 
can carry from 1 up to 4 bits of information. Thus it is possible to build the 
effective TMCC-based QKD protocols utilizing 4-letter alphabets for beams 
carrying about 3-5 photons in average which will raise the measurement 
information gain to 2 bits and the 8-letter alphabets for more intensive beams 
which will result in the effectiveness of up to 4 bits per measurement. 

Here we examine two possible alphabet extensions for the TMCC chan- 
nels, containing 4 and 8 state "letters". 

The quaternary channel with two bits per measurement capacity can be 
established on the basis of the TMCC beams which are distinguished by the 
photon numbers between 4 possible states (see figure Ej): 



{n < [(n)] - 1} ^00 (letter 0) 
. {n= [(n)] } ^01 (letter 1) 
^ ^ {n = [(n)] + 1} ^10 (letter 2) ^ ' 

{n > [{n)] + 2} ^11 (letter 3) 
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Figure 2: Graphical representation of three alphabet sets for a channel based 
on the multiphoton pulses: a) usual 2-letter alphabet with the capacity of 1 
bit per photon- number measurement; b) 4- letter alphabet with 2 bits avail- 
able from each measurement and c) 8-letter alphabet with 3 bits information 
gain for each measurement. 



Knowing the photon numbers registration probability distribution for a 
TMCC-beam (j2I) one can easily estimate the probability for each of the 4 
quart states ^ realization: 



^o(A) 
P2(A) = 



[(">]-! 
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n=0 



A 



2n 



/o(2|A|) — 

I |;^|2([(n>]+l) 

/o(2|A|)([(n)] + l)! 



|2[(n>] 



^3(A) 



/o(2|A|) ' 

oo lAP" 



/o(2|A|) 



E 



nl 



(8) 



n=[(n)]+2 

These probability values can be then used for estimating the Shannon 
entropy © of a photon-number measurement on a TMCC-beam with four 
possible interpretation outcomes, which is the information gain for such a 
measurement. 

The octuple TMCC-based channel with the capacity of three bits per mea- 
surement can be established in a similar way if the states are distinguished 
by 8 possible measurement outcomes which differ in photon numbers (see 
figure El) : 
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Again, knowing the distribution (j21) we can obtain the probabihty for each 
octo-bit value occurrence and thus build the Shannon information available 
from a measurement. 

The dependencies for the measurement information gain for 2-, 4- and 
8-letter alphabets on the state average photon number are given on a graph 
at ©. 
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Figure 3: Shannon entropies characterizing information gain of the TMCC- 
states photon-number measurements for binary, quaternary and octuple al- 
phabets 



4 Security 

The security of a quantum channel i.e. the impossibility to carry out a suc- 
cessful eavesdropping is obviously the most important property for any QKD 
scheme. Traditionally the security of a quantum channel is examined in the 
frames of the two approaches - the ideal and the realistic ones jT3]. In the 
ideal case the eavesdropper Eve is supposed to have the unlimited technologi- 
cal power with possibilities restricted only by the laws of quantum mechanics 
|14j . The realistic approach takes into account the technical possibilities of 
an eavesdropper compatible with today's and foreseeable technology at this 
the most successful realistic eavesdropping techniques on the secure quantum 
channels are the intercept-resend strategy also referred to as state cloning and 
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the beam splitting The most general security criterion known from the 
classical cryptography already states that Bob has to possess more informa- 
tion on the transferred key than Eve (if the Bob's mode was eavesdropped). 
In this case the privacy amplification post-transfer algorithms will be helpful 
in distilling the truly secure key, otherwise they will fail [3 . 

The eavesdropping in quantum cryptography is usually detected by check- 
ing the QBER (quantum bit error rate) which is the measure of the errors 
in the obtained key. Since all of the errors are considered to be caused by 
an eavesdropper, knowing the QBER one can estimate how much informa- 
tion on the key does the eavesdropper have and thus determine is the key 
distillation will be successful. 

The TMCC-based scheme was examined against the realistic eavesdrop- 
ping and shown to be secure against splitting and cloning attacks. In the case 
of the beam splitting this is quite intuitive because the installation of a split- 
ter at any of the modes removes the correlation between modes thus simply 
destroying the channel (for more detailed examination of a beam splitting 
attack on a TMCC-channel see [HE]). In the case of a state cloning it was 
shown that eavesdropper significantly changes the statistics of the re-emitted 
mode which can be detected by the local calculations of the Mandel param- 
eter or the distances between the received and the expected states' density 
matrices ^ . In this work we estimate the security of the TMCC-based chan- 
nel in the terms of the QBER, which is introduced to the channel upon the 
eavesdropping. We use this measure to compare the security of the TMCC 
QKD scheme for different alphabet sizes. 

Let's consider Eve carrying out a cloning intercept-resend attack on a 
TMCC-based channel. In order to do so she installs a photon-counting de- 
tector which measures one of the modes (suppose the one which goes to Bob) 
and a TMCC laser source assigned for re-creating the state (figlH). 

For each incoming pulse (i.e. in each time slot) Eve measures the photon 
number n and tries to re-emit the same photon number in the Bob's direction. 
We assume Eve calculates the value of state parameter A„ which corresponds 
to the photon number n to be emitted and sets her source up to this value. 
Though due to the quantum fluctuations she is unable to emit exactly the 
same number and thus Bob obtains the state which density matrix ps, differs 
from the original pb measured by Eve. This re-emitted state matrix is the 
mixture of the k-photon states 

oo 

PB = T.Pk \k) {k\ (10) 

k=0 
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Figure 4: State cloning intercept-resend eavesdropping attack on a TMCC- 
based channel 
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The probability for Bob to incorrectly interpret the received state i.e. to 
obtain the wrong letter x of the alphabet set X of size m (so that X = 
{xo...Xm}) is equal to 

Perr=T.-i^-PB{x\x)), (12) 

where Pb{x\x) is the probability for Bob to obtain the correct letter x 
given Alice obtained the same letter x. The QBER introduced by Eve for 
each intercepted bit is then 

Perr/bit ~, Perr' (-^2) 

log2 m 

The sum in[T21can be presented and calculated through the probability 
distributions as 
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Y,PBix\x)= PkiXn)PniX)+ E i^fe ( A„) F„( A) + ^ ( A) , (14) 

x&X k,n=0 k,n=nm 



n=ni 



where no is the photon number corresponding to the first alphabet letter 
Xq and Um is the photon number corresponding to the last letter Xm, -Pn(A) 
is the probability distribution Q and 



Pk{K, 



I A, 



i2fe 



k\'W\Xn\) 



(15) 



Hence the QBER can be calculated numerically. The results are presented 
on the graphs at figElas the QBER dependence on the average photon number 
(i.e. on the original pulse intensity) for different alphabet sizes. One can 
easily see that QBER introduced for each intercepted bit during the state 
cloning attack on a 2-letter (1-bit) alphabet channel is about 20%, growing 
to about 50% in the case of 4-letter (2-bit) case and exceeding 70% for the 
8-letter (3-bit) alphabet. Thus the TMCC-based QKD protocol turns out to 
be more secure at the larger alphabets. 
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Figure 5: QBER introduced by Eve for each intercepted bit during the state 
cloning attack with a TMCC-source on a TMCC-based channel for different 
alphabet sizes dependence on the average photon number 



If Eve uses a usual single mode laser source, producing a coherent beam 
with the Poisson statistics for the TMCC-state cloning, the calculations give 
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QBER values of about 30% for 2-letter, up to 60% for 4-letter and over 80% 
for the 8-letter alphabet thus proving that TMCC-state cloning based on a 
usual laser source is even less effective. 

5 Conclusions 

The quantum cryptography scheme with larger alphabets based on the use 
of the two-mode coherently correlated multiphoton beams is proposed. The 
alphabet extension is shown to result in the increase of the effectiveness of 
the QKD scheme. The protocol security against the realistic state cloning 
is examined in terms of the introduced QBER. It is shown that the TMCC- 
based QKD scheme becomes more secure for the larger alphabet sets i.e. for 
the more intense laser pulses. 
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